IXPath is committed to protecting personal and research data processed through its services and to using such data only to the extent necessary for the purpose for which it was collected or provided.
1. Data Minimization
IXPath follows the principle of data minimization and does not seek to collect or process more personal information than is reasonably required for a service.
In research projects, names, identification numbers, file numbers, and other direct identifiers should be removed whenever reasonably possible.
2. Health and Research Data
Directly identifiable health or personal data should be provided to IXPath only where it is necessary for the project, its use is lawful, required permissions or approvals are in place, and the nature of the project permits its processing.
3. Responsibility of the Data Provider
The person providing data is responsible for ensuring the lawfulness of its collection and use, obtaining required permissions, and complying with the terms of applicable ethical or institutional approvals and any data-subject consents that may be required.
4. Access Control
Access to data is limited to persons whose duties require it. Employees, experts, and service providers involved in the work are subject to confidentiality and data-protection obligations appropriate to their roles.
5. Security Measures
IXPath applies appropriate administrative and technical measures intended to protect data against unauthorized access, loss, unlawful disclosure, unauthorized alteration, and misuse.
6. Use of Data
Research-project data is not unlawfully used outside the agreed scope of the service, and personal or research data is not sold to third parties.
7. Sensitive Data
Health and other sensitive personal data are subject to a higher level of confidentiality and protection. Confidentiality obligations continue for as long as required by the nature of the data or applicable legal requirements.
8. Projects Involving Extensive Data Processing
Where a project involves extensive processing of personal or health data, IXPath may use a separate agreement or addendum addressing the data types, processing purpose, authorized persons, safeguards and storage, retention period, incident handling, and data return or destruction after project completion.